arXiv

Inference Cost Attacks for Retrieval-Augmented Large Language Models

Title: Inference Cost Attacks for Retrieval-Augmented Large Language Models

Abstract: While Retrieval-Augmented Generation (RAG) systems significantly enhance Large Language Models (LLMs), they incur substantial inference expenses due to a complex, multi-stage pipeline that dynamically fetches and integrates data from external repositories. This elevated operational expenditure creates a significant security gap, rendering these systems susceptible to Inference Cost Attacks (ICAs). However, current ICAs frequently depend on the unrealistic premise of direct prompt manipulation. We contend that a more viable and dangerous threat vector involves contaminating external knowledge bases, such as internet-based repositories. To address this, we present the Retrieval-Augmented Inference Cost Attack (RA-ICA), a new adversarial framework designed to exploit the computational overhead of RAG-enhanced LLMs by introducing malicious documents into the external corpus. We implement this attack through Computational Resource Exhaustion via External Poisoning (CREEP), a framework that utilizes LLM agents to automatically generate malicious documents. These documents are engineered to be semantically relevant for retrieval while simultaneously triggering an anomalous spike in token usage during inference. To maximize the efficacy of this approach, we developed Memory-Augmented Group Relative Policy Optimization (MA-GRPO), a novel reinforcement learning algorithm. This algorithm fine-tunes the agents by leveraging a dynamic memory of historically successful adversarial documents. Our extensive experiments, conducted across three real-world datasets, reveal that RA-ICA can escalate token consumption by as much as 13.12 times with a success rate exceeding 90%, all while maintaining the integrity of the generated responses.


Source: arXiv Generated at: 2026-06-03 00:00:00 UTC

Related Articles

TikTok Billionaire Tops Ambani as Asia’s Second-Richest
Bloomberg

TikTok Billionaire Tops Ambani as Asia’s Second-Richest

TikTok founder surpasses Mukesh Ambani to become Asia’s second-richest person, marking a significant shift in the region...

Publishers in UK can opt out of Google AI search results
BBC News

Publishers in UK can opt out of Google AI search results

UK publishers can now opt out of Google’s AI search summaries, a CMA ruling designed to boost their bargaining power and...

Kioxia Edges Nearer Toyota’s Market Cap in Shakeup to Japan Inc.
Bloomberg

Kioxia Edges Nearer Toyota’s Market Cap in Shakeup to Japan Inc.

Kioxia’s market cap nears Toyota’s, signaling a major shift in Japan’s corporate hierarchy. This narrowing gap highlight...

Reuters

Morning Bid: Marvell, a fitting name for the latest AI darling

Reuters highlights Marvell as a top AI stock, noting its name perfectly suits its status as the newest market darling.

Financial Times

Tim Hayward: I built the Jaguar E-Type of computer keyboards

Tim Hayward compares his bespoke keyboard designs to the Jaguar E-Type. He explores high-end customization for personal ...

Financial Times

AI Labs: Zuckerberg’s $100bn gamble

Meta’s $100 billion AI investment aims to secure AI dominance, but questions remain whether sheer spending can outpace c...